Skip to content
The products offered on this site are intended for research purposes only. They are not intended for consumption or use by humans or animals.
purepoint SUPPLY
  • Shop
  • Vidensbase
  • Juridisk center
  • Contact
  • FAQ
  • Beregner
  • Kvalitet
  • Levering i EU
  • Om os
Languages
🇵🇱PL🇬🇧EN🇩🇪DE🇩🇰DA
Currencies
🇩🇰DKK🇵🇱PLN🇪🇺EUR🇬🇧GBP🇺🇸USD🇸🇪SEK🇨🇿CZK
🇵🇱PolskiPL🇬🇧EnglishEN🇩🇪DeutschDE🇩🇰DanskDA
🇩🇰Dansk kroneDKK🇵🇱Polski złotyPLN🇪🇺EuroEUR🇺🇸US dollarUSD🇬🇧British poundGBP🇸🇪Svensk kronaSEK🇨🇿Česká korunaCZK
Welcome to PUREPOINT Log in Create account
0
Home / Legal Center / Cookies Policy

Legal document

Cookies Policy

Operator
FIRSTSTONE TRADING sp. z o.o.
Version
2.0
Effective date
2026-06-06
Last updated
2026-08-09
Language
Polish
Legal contact
compliance@purepoint.pl

Operator: FIRSTSTONE TRADING spółka z ograniczoną odpowiedzialnością (abbreviation: FIRSTSTONE TRADING sp. z o.o.) KRS: 0001254766 | NIP: 7831958614 Registry court: District Court Poznań – Nowe Miasto i Wilda in Poznań, VIII Commercial Division of the National Court Register Date of registration: 17 February 2026 Registered office (KRS): ul. Wierzbięcice 44A/40A, 61-568 Poznań, województwo wielkopolskie Voivodeship Correspondence / Shop service address: ul. Wierzbięcice 44A/40A, 61-568 Poznań (100 shares of PLN 50.00 each) Representation: Krystian Dawidowski — Member of the Management Board (sole-member management board, independent representation) Electronic Delivery Address (ADE): AE:PL-21312-60691-FGBFV-19 Shop domain: purepoint.pl Privacy contact: compliance@purepoint.pl Shop contact: contact@purepoint.pl

Document version: 2.0 Effective date: 6 June 2026 Review cycle: quarterly (next: 6 September 2026)


Table of contents

  1. § 1. General provisions and definitions
  2. § 2. What cookies and similar technologies are
  3. § 3. Legal bases for the use of cookies
  4. § 4. Categories of cookies used in the Shop
  5. § 5. Operator’s decision — selection of Plausible Analytics
  6. § 6. Table of all first-party cookies
  7. § 7. Third-party cookies
  8. § 8. Cookie banner — symmetric model following the UODO (Polish DPA) decision 02/2025
  9. § 9. Consent management and the preferences panel
  10. § 10. Impact on the functioning of the Shop following refusal
  11. § 11. Policy amendment procedure
  12. § 12. Bibliography and legal acts
  13. § 13. Document change history
  14. § 14. Final clause

§ 1. General provisions and definitions

  1. This Cookies Policy (hereinafter: the “Policy”) describes the principles for the use of cookies and similar terminal information technologies (local storage, session storage, IndexedDB, pixel tags) in the online Shop available at https://purepoint.pl (hereinafter: the “Shop”), operated by FIRSTSTONE TRADING sp. z o.o. (hereinafter: the “Operator”).
  2. The Policy supplements the Privacy Policy (document no. 06) and the Shop Terms and Conditions (document no. 01). In the event of any conflict between the documents, the Privacy Policy shall prevail as regards the protection of personal data, and this Policy shall prevail as regards terminal technology.
  3. Definitions used in the Policy: – Cookie / Cookie file — a small text file stored in the memory of the Purchaser’s terminal device (computer, smartphone, tablet) by the web browser at the request of the server or of a script of the domain being visited, used to store information about the session, preferences, login status or an analytics identifier. – Similar technology — any technology enabling the storing of information in a terminal device or the gaining of access to information already stored there, in particular local storage, session storage, IndexedDB, fingerprinting, web beacons, pixel tags, application SDKs. – First-party cookie — a cookie set by the purepoint.pl domain, a subpage of which the Purchaser is currently visiting. – Third-party cookie — a cookie set by a domain other than purepoint.pl (e.g. js.stripe.com) loaded as part of a Shop page. – Session cookie — a cookie deleted automatically once the browser is closed. – Persistent cookie — a cookie with a defined expiry date, stored in the device until the retention period elapses or until it is deleted manually. – Strictly necessary cookie — a cookie without which the service selected by the Purchaser (login, basket, WooCommerce basket, payment) cannot be provided; exempt from the consent requirement. – Analytics cookie — a cookie used to measure traffic, compile statistics and optimise UX; requires consent unless it is a first-party analytics cookie meeting the conditions of EDPB Guidelines 5/2020 and is used solely by the Operator. – Marketing cookie — a cookie used for profiling, retargeting, behavioural advertising; requires consent. – Banner — the first interface layer informing the Purchaser about cookies and collecting consents. – Preferences panel — an interface enabling granular management of consents to cookies. – Purchaser — a natural person, legal person or organisational unit placing or able to place an Order in the Shop, within the meaning of the Terms and Conditions (document 01). – Qualified Purchaser — a Purchaser meeting the requirements of § 3 of the Shop Terms and Conditions and holding an active Qualified Profile Declaration (KOP); the only category of Purchasers entitled to acquire Research Materials in the Shop. – Operator / we — FIRSTSTONE TRADING sp. z o.o., with the registration details indicated in the header.
  4. All other capitalised terms not defined in this Policy shall have the meaning ascribed to them in the Shop Terms and Conditions or in the Privacy Policy.

§ 2. What cookies and similar technologies are

  1. Cookies are small text files (usually up to 4 KB) which the Shop server, or a JavaScript script loaded on a Shop page, asks the Purchaser’s browser to store in the memory of the terminal device. A cookie consists of a name (key), a value (usually a string of characters, an identifier or a hash), an expiry date, the path and domain to which it is assigned, and security flags (Secure, HttpOnly, SameSite).
  2. With each subsequent HTTP request to the same domain, the browser automatically attaches the cookies applicable to the given path, by means of which the server “recognises” the Purchaser between requests — without cookies, every click would require logging in again, would empty the basket and would lose the language selection.
  3. Similar terminal information technologies (local storage, session storage, IndexedDB) operate in an analogous manner but store data solely on the browser side — they are not automatically attached to HTTP requests. The Operator uses them marginally (including to remember the visibility of compliance messages once the age-of-majority threshold has been accepted).
  4. A pixel tag (a transparent 1×1 px image) and a web beacon are techniques for tracking events (the opening of a message, the display of a page). The Operator does not use advertising pixel tags. The newsletter open-measurement pixel is used by Sendinblue SAS under the Brevo brand on the basis of a separate marketing consent (see Privacy Policy § 8).
  5. Fingerprinting (recognising a device by browser features, fonts, GPU) is not used by the Operator or by third parties loaded on a Shop page. Plausible Analytics does not use fingerprinting — details in § 5.

§ 3. Legal bases for the use of cookies

The use of cookies in the Shop is based on three parallel legal bases, the distinction between which is key to understanding when the Purchaser’s consent is required and when it is not.

3.1. Art. 173 of the Telecommunications Law (PT)

[VERIFY — PKE 2024 replaced the Telecommunications Law. The Act of 12 July 2024 — Electronic Communications Law (Journal of Laws 2024 item 1221), in force from 10 November 2024, repealed, among others, the provisions of Art. 173 of the Telecommunications Law governing cookies and transferred the principle of consent to access to a terminal device into the PKE. The entire argumentation below based on Art. 173 PT requires rewriting to the relevant PKE provision — the exact article number and wording to be confirmed by legal counsel. The marker concerns ALL references to “Art. 173 PT” and “Art. 172 PT” in this document, including the tables in § 4, § 6 and § 7.]

The Act of 16 July 2004 — Telecommunications Law (consolidated text: Journal of Laws 2024 item 34, as amended), hereinafter: PT, provides in Art. 173:

“1. The storing of information or the gaining of access to information already stored in the telecommunications terminal device of a subscriber or end user is permitted, provided that: 1) the subscriber or end user is, in advance, directly informed in an unambiguous, easy and comprehensible manner of: a) the purpose of storing and gaining access to that information, b) the possibility of his determining the conditions for storing or gaining access to that information by means of the settings of the software installed in the telecommunications terminal device used by him or the configuration of the service; 2) the subscriber or end user, having received the information referred to in point 1, consents thereto; 3) the stored information, or the gaining of access thereto, does not cause configuration changes in the subscriber’s or end user’s telecommunications terminal device or in the software installed in that device. 2. The subscriber or end user may give the consent referred to in para. 1 point 2 by means of the settings of the software installed in the telecommunications terminal device used by him or the configuration of the service. 3. The conditions referred to in para. 1 shall not apply if the storing of, or the gaining of access to, the information referred to in para. 1 is necessary in order to: 1) carry out the transmission of a communication via a public telecommunications network; 2) provide a service supplied by electronic means which the subscriber or end user requests to be provided.”

Art. 173 para. 3 point 2 PT gives rise to an exemption from the consent requirement for strictly necessary cookies — i.e. those the storing of which is necessary in order to provide the service requested by the Purchaser (login, basket, WooCommerce session, language identifier, marker indicating that the age gate has been passed).

3.2. Art. 5 para. 3 of Directive 2002/58/EC (ePrivacy)

Directive 2002/58/EC of the European Parliament and of the Council of 12 July 2002 concerning the processing of personal data and the protection of privacy in the electronic communications sector (Directive on privacy and electronic communications; hereinafter: ePrivacy), as amended by Directive 2009/136/EC, introduces in Art. 5 para. 3 the consent-based principle for any technology for accessing information in a terminal device. The exception covers cookies that are “strictly necessary” for the provision of an information society service explicitly requested by the user.

The Court of Justice of the European Union, in its judgment of 1 October 2019 in Planet49 (C-673/17), held that: – consent to analytics and marketing cookies must be active (opt-in), and not presumed; – pre-selected checkboxes (“a box ticked by default”) do not satisfy the consent requirement within the meaning of Art. 5 para. 3 of Directive 2002/58/EC in conjunction with Art. 4 point 11 and Art. 7 of the GDPR (RODO); – the information must cover the period of activity of the cookies and the range of recipients of the data.

3.3. Art. 6 para. 1 of the GDPR (RODO)

Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (hereinafter: the GDPR (RODO)), applies where cookies lead to the processing of personal data (e.g. a pseudonymous identifier, an IP address). – For strictly necessary cookies, the legal basis for processing the data is Art. 6 para. 1 point (f) GDPR (RODO) — the legitimate interest of the Operator consisting in ensuring the operation of the Shop, the session, the basket and security. – For analytics and marketing cookies, the legal basis would be Art. 6 para. 1 point (a) GDPR (RODO) — the Purchaser’s consent. The Operator does not use marketing cookies or third-party analytics cookies — details in § 5.

3.4. EDPB Guidelines 5/2020

The European Data Protection Board (EDPB) in its Guidelines 5/2020 on consent under Regulation 2016/679 (adopted on 4 May 2020) clarified that: – consent must be freely given — scrolling the page, closing the banner, continuing to use the Shop does not constitute consent; – consent must be informed — the information must be presented in a clear and comprehensible manner; – consent must be unambiguous — an active action is required (clicking the “I accept” button); – it must be possible to withdraw consent easily — at least as easily as it was given.

3.5. The UODO (Polish DPA) decision 02/2025

The President of the Personal Data Protection Office, by decision of 2025 (number 02/2025, fine EUR 420,000), confirmed that an asymmetric cookie banner — in which the “Accept all” button is visually more prominent than “Reject all”, or in which the refusal option requires additional clicks — infringes the requirement that consent be freely given. In response to that decision the Operator implemented a symmetric banner — details in § 8.


§ 4. Categories of cookies used in the Shop

The Operator classifies the cookies used in the Shop into three categories. The classification determines the legal basis and the consent requirement.

Category Consent requirement Legal basis Used in the Shop
Strictly necessary NO — exempt under Art. 173 para. 3 PT and Art. 5(3) ePrivacy Art. 6 para. 1 point (f) GDPR (RODO) (legitimate interest) YES — session, basket, login, language, age gate, compliance declarations, Stripe integration, fonts
Analytics (statistical) As a rule YES — exception for first-party analytics meeting the CNIL/EDPB requirements Art. 6 para. 1 point (a) GDPR (RODO) (consent) or point (f) in the case of aggregated analytics NO — the Operator uses cookieless first-party analytics (Plausible) — see § 5
Marketing (advertising) YES Art. 6 para. 1 point (a) GDPR (RODO) (consent) NO — the Operator does not conduct behavioural advertising or retargeting

Consequence: The Shop uses strictly necessary cookies only. Consent to cookies is not required for normal use of the Shop, because all cookies present in the Shop fall under the exemption of Art. 173 para. 3 point 2 PT. The cookie banner nevertheless appears — in an informational function and as a mechanism for confirming that the Policy has been read (in accordance with the accountability principle of Art. 5 para. 2 GDPR (RODO)).


§ 5. Operator’s decision — selection of Plausible Analytics

5.1. Content of the decision

Having analysed the available web analytics tools (Google Analytics 4, Matomo on-premise, Plausible Analytics, Fathom, Simple Analytics, Umami), the Operator selected Plausible Analytics as its production solution, provided by:

Plausible Insights OÜ Tallinn, Estonia (registered office). Register: Republic of Estonia registration number 14709274. Status: a private company (osaühing) under Estonian law.

The decision was taken on 6 June 2026 and is a final decision (status v2 — previously the project envisaged Google Analytics 4 with IP anonymisation; the pivot is justified below).

5.2. Justification for the selection — analysis of seven criteria

Criterion 1 — cookielessness. Plausible Analytics is a cookieless tool: visit measurement is based on a heuristic for counting unique visitors by hashing a combination (date + IP + User-Agent + domain) that is rotated daily. It does not store any cookies in the Purchaser’s terminal device. Consequently, the exemption of Art. 173 para. 3 PT and Art. 5(3) ePrivacy applies, because there is no “storing of information in a terminal device”.

Criterion 2 — data minimisation (Art. 5 para. 1 point (c) GDPR (RODO)). Plausible collects: the type of page (URL), the referrer, the User-Agent (for browser/OS/device aggregation), the country based on the IP address (geocode → IP discarded). It does not collect: advertising identifiers, fingerprint, cross-site history, micro-scale behavioural data.

Criterion 3 — full data localisation within the EEA. Plausible Insights OÜ has data centres solely within the European Economic Area (Germany, Estonia). There is no transfer whatsoever to third countries. Schrems II (C-311/18) does not apply, because there is no transfer of data to a third country.

Criterion 4 — anonymisation at the engineering level. The Purchaser’s IP address is not stored; it serves solely to generate a hash in memory and for geocoding (country) — after which it is immediately discarded. After the hashing process there is no technical possibility of restoring the IP address.

Criterion 5 — open source and audit. The source code of Plausible Community Edition is publicly available on GitHub (AGPL-3.0 licence). This enables independent auditing of the measurement mechanisms and verification of conformity with the manufacturer’s declarations.

Criterion 6 — DPA and SCC. Despite the absence of any transfer to third countries, the Operator has concluded with Plausible Insights OÜ a data processing agreement (DPA) compliant with Art. 28 GDPR (RODO). The agreement introduces: an obligation of confidentiality, the safeguards of Art. 32 GDPR (RODO), audit rights, sub-processing requiring consent, and the return/erasure of data upon termination of the cooperation.

Criterion 7 — absence of conflict with US law. Plausible Insights OÜ is subject to Estonian law. It is not a subsidiary of US providers. It is not subject to the CLOUD Act, FISA 702 or Executive Order 12333. This eliminates the risk which was the basis of the Schrems II judgment in relation to Google.

5.3. Why the pivot away from GA4

The earlier Shop project (v1.0 of the legal documents dated 22-24 May 2026) envisaged Google Analytics 4 with IP anonymisation and the Consent Mode v2 option enabled. Following a legal-risk analysis — in particular: – the CNIL decisions of February 2022 (France) and the Garante decisions of June 2022 (Italy) holding the use of GA on European sites to be an infringement of Art. 44-49 GDPR (RODO); – uncertainty as to the effectiveness of the EU-US Data Privacy Framework (challenged before the CJEU); – the need to implement a symmetric banner with opt-in following the UODO (Polish DPA) decision 02/2025 (effect: 60-80% loss of measurement); – the simplicity of a cookieless architecture; — the Operator took the strategic decision to abandon GA4 in favour of Plausible.

5.4. Plausible opt-out mechanism

Even though Plausible does not require consent on the basis of Art. 173 para. 3 PT, the Operator enables Purchasers to make a voluntary opt-out from counting in Plausible. The mechanism: – setting the variable localStorage.plausible_ignore = "true" in the Purchaser’s browser (via the “Disable statistics” link in the Shop footer); – once the variable is set, the Plausible script does not send measurement events from the Purchaser’s device; – the variable remains active until the Purchaser clears the local storage.


§ 6. Table of all first-party cookies

The table below lists the complete set of cookies used in the Shop in the purepoint.pl domain. The Operator undertakes to keep the table up to date — each change will be reflected in the Change History (§ 13).

Cookie name Provider / domain Purpose Retention Type Legal basis
wordpress_* purepoint.pl (WordPress core) Identification of the logged-in user in the administration panel; prevention of session theft Session Strictly necessary Art. 173 para. 3 point 2 PT + Art. 6 para. 1 point (f) GDPR (RODO)
wordpress_logged_in_* purepoint.pl (WordPress core) Confirmation of login status on front-end pages Session Strictly necessary Art. 173 para. 3 point 2 PT + Art. 6 para. 1 point (f) GDPR (RODO)
wordpress_test_cookie purepoint.pl (WordPress core) Test of cookie support in the browser prior to login Session Strictly necessary Art. 173 para. 3 point 2 PT + Art. 6 para. 1 point (f) GDPR (RODO)
wp_woocommerce_session_* purepoint.pl (WooCommerce) Basket session identifier — maintaining the basket contents between requests 48 hours Strictly necessary Art. 173 para. 3 point 2 PT + Art. 6 para. 1 point (f) GDPR (RODO)
woocommerce_cart_hash purepoint.pl (WooCommerce) Hash of the basket contents — detecting changes and reflecting them in the UI Session Strictly necessary Art. 173 para. 3 point 2 PT + Art. 6 para. 1 point (f) GDPR (RODO)
woocommerce_items_in_cart purepoint.pl (WooCommerce) Indicator of the presence of items in the basket (1/0) Session Strictly necessary Art. 173 para. 3 point 2 PT + Art. 6 para. 1 point (f) GDPR (RODO)
pp_age_gate_passed purepoint.pl (Shop) Marker indicating that the age gate has been passed (confirmation of age of majority) — eliminating the need to display it again 90 days Strictly necessary Art. 173 para. 3 point 2 PT + Art. 6 para. 1 point (f) GDPR (RODO) (compliance)
pp_compliance_acks purepoint.pl (Shop) Marker confirming acknowledgement of compliance warnings (research-use-only, restrictions on use) — eliminating repeated display 90 days Strictly necessary Art. 173 para. 3 point 2 PT + Art. 6 para. 1 point (f) GDPR (RODO) (compliance)
pll_language purepoint.pl (Polylang) Interface language selection (PL/EN) 1 year Strictly necessary Art. 173 para. 3 point 2 PT + Art. 6 para. 1 point (f) GDPR (RODO)
wp_lang purepoint.pl (WordPress core) Administration panel language (for logged-in users) Session Strictly necessary Art. 173 para. 3 point 2 PT + Art. 6 para. 1 point (f) GDPR (RODO)
pp_consent_record purepoint.pl (Shop) Record of the choice made in the cookie banner (accept / reject / customise) — evidence of the consent given 12 months Strictly necessary (accountability, Art. 5 para. 2 GDPR (RODO)) Art. 6 para. 1 point (f) GDPR (RODO)
XSRF-TOKEN / wp_nonce_* purepoint.pl (WordPress security) Protection against CSRF (Cross-Site Request Forgery) attacks in forms Session Strictly necessary Art. 173 para. 3 point 2 PT + Art. 6 para. 1 point (f) GDPR (RODO) (security)
plausible_ignore (local storage, optional) purepoint.pl (Plausible opt-out) Marker of a voluntary opt-out from Plausible measurement — set by the Purchaser Persistent (until the local storage is cleared) Strictly necessary (Purchaser control) Art. 6 para. 1 point (f) GDPR (RODO)

In total: 13 cookie files / local storage entries, of which 100% qualify as strictly necessary within the meaning of Art. 173 para. 3 point 2 PT and Art. 5 para. 3 second sentence of Directive 2002/58/EC.


§ 7. Third-party cookies

The Shop loads a minimal number of third-party resources, limited to those that are directly necessary to provide the service requested by the Purchaser. The Operator does not load advertising, marketing or analytics scripts of third parties.

7.1. Stripe Payments Europe Limited

Provider: Stripe Payments Europe Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland. Domains: js.stripe.com, m.stripe.network, q.stripe.com. Scope: the payment gateway scripts and the Stripe Elements widget loaded solely on the payment process page (/koszyk, /zamowienie, /platnosc) after Stripe is selected as the payment method. Stripe cookies (example): – __stripe_mid (payment device identifier, retention 1 year) — necessary for fraud detection; – __stripe_sid (payment session identifier, retention 30 min) — necessary for conducting the transaction.

Legal qualification: strictly necessary within the meaning of Art. 173 para. 3 point 2 PT — processing necessary to provide the payment service explicitly requested by the Purchaser through the selection of that method in the basket. The Stripe gateway does not load until the Purchaser initiates the payment process.

GDPR (RODO): Stripe is an independent controller as regards fraud detection and the PSD2/AML regulatory requirements. Details of the controller-to-controller relationship are described in the Privacy Policy § 8 (Recipients of data) and in the payment operator’s privacy policy at https://stripe.com/privacy.

7.2. Google Fonts (Google Ireland Limited)

Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Domain: fonts.gstatic.com, fonts.googleapis.com. Scope: the loading of the typographic font files Inter, Source Serif, JetBrains Mono — the foundation of the Shop’s visual layer. Cookies: Google Fonts does not set cookies in the fonts.gstatic.com domain (Google declares the absence of cookies for this subdomain; the mere downloading of a font file does not require cookies). There is, however, an HTTP request in the course of which Google records the Purchaser’s IP address in the server logs.

Legal qualification: strictly necessary — the fonts are an integral part of the Shop’s presentation layer. The Operator is considering hosting the fonts locally in order to eliminate the external request — a change planned for v2.1 of the document (review: September 2026).

GDPR (RODO): the legal basis is Art. 6 para. 1 point (f) GDPR (RODO) — the legitimate interest of the Operator consisting in providing a consistent presentation layer. Google Ireland Limited is the controller of the technical data in the logs of its own server.

7.3. Plausible Insights OÜ — no cookies

Even though Plausible is a third party, it does not set cookies in the Purchaser’s device (see § 5). The plausible.js script loaded from the plausible.io domain sends measurement events but does not store any data in the device’s memory. For this reason Plausible is not subject to the consent requirement on the basis of Art. 173 PT and Art. 5(3) ePrivacy.

7.4. Sendinblue SAS (Brevo) — solely in the newsletter

The Brevo e-mail open tracker (a 1×1 pixel in newsletter messages) operates solely in the e-mail messages sent to newsletter Subscribers, not on a Shop page. It does not generate cookies in the purepoint.pl domain. Details in the Privacy Policy § 8.


§ 8. Cookie banner — symmetric model following the UODO (Polish DPA) decision 02/2025

8.1. Legal requirements arising from the UODO (Polish DPA) decision 02/2025

The President of the Personal Data Protection Office, in decision no. 02/2025, when imposing a fine of EUR 420,000, established the following standards for the cookie banner:

  1. Three options on the first layer: Accept all / Reject all / Customise — none of them may be hidden under “Advanced settings” or “Learn more”.
  2. Visual symmetry: all three buttons must have the same size, colour, contrast, font and padding. It is impermissible to distinguish “Accept” with a brand colour while “Reject” is merely a text link.
  3. Equal distance from the eye: no F-pattern hierarchy favouring acceptance.
  4. No dark patterns: techniques that divert attention are impermissible (e.g. a window requiring five clicks for refusal versus one for acceptance).

8.2. The Operator’s implementation

The Shop has implemented a banner compliant with the 3-button symmetric model:

┌─────────────────────────────────────────────────────────────────┐
│  Cookies                                                        │
│                                                                 │
│  The purepoint.pl Shop uses only cookies that are strictly      │
│  necessary for the operation of the Shop (login, basket, age    │
│  gate). We conduct analytics in a cookieless manner within the  │
│  EEA (Plausible). We do not use marketing or advertising        │
│  cookies.                                                       │
│                                                                 │
│  [Accept all]  [Reject all]  [Customise]                       │
│                                                                 │
│  Details: Cookies Policy | Privacy Policy                       │
└─────────────────────────────────────────────────────────────────┘

Button specification: – all three buttons in an identical flex container with gap: 12px; – background: surface secondary colour (#1A1A1A), text: white, border-radius 4px, padding 12px 24px; – font-weight: 500 for all three; – font-family, font-size, line-height identical; – first focus after loading: not set by default (no pre-selection).

Selecting “Accept all” → sets the record pp_consent_record = {analytics: false, marketing: false, necessary: true} (analytics false, because Plausible does not use cookies). The banner disappears.

Selecting “Reject all” → sets pp_consent_record = {analytics: false, marketing: false, necessary: true} and additionally localStorage.plausible_ignore = "true" (disabling Plausible). The banner disappears.

Selecting “Customise” → opens the Preferences panel (§ 9).

8.3. No banner action = no consent

The Operator does not treat scrolling the page, closing the banner (X), clicking outside the banner or any further use of the Shop as consent to analytics or marketing cookies. Given that the Shop does not use such cookies, the Purchaser’s choice in the banner does not affect any analytics or marketing cookies — it affects solely the opt-out from Plausible.

8.4. Display frequency

The banner appears: – on the first visit from a given browser / device; – after the Purchaser clears the browser’s cookies / memory; – once every 12 months (re-confirm — an EDPB indication for maintaining informed consent).


§ 9. Consent management and the preferences panel

9.1. Access to the panel

The Purchaser has access to the Cookie preferences panel at any time via: – the “Cookies — manage consents” link in the Shop footer (visible on every subpage); – the “Customise” button in the banner on the first visit; – the direct URL: https://purepoint.pl/polityka-cookies/?panel=open (reserved).

9.2. Content of the panel

The preferences panel presents:

  1. Strictly necessary cookies — a description, a list of the specific cookies (in accordance with the table in § 6), a checkbox “Always on — non-editable”;
  2. Analytics cookies — a description of Plausible Analytics, information about its cookielessness, a “Disable Plausible measurement” toggle (once selected → sets localStorage.plausible_ignore = "true");
  3. Marketing cookies — a description: “The Shop does not use marketing or advertising cookies. This section is retained as information for the Purchaser” (the toggle is inactive);
  4. Buttons: “Save preferences” / “Close”.

9.3. Withdrawal of consent

Any consent given by the Purchaser may be withdrawn just as easily as it was given (Art. 7 para. 3 second sentence GDPR (RODO); EDPB Guidelines 5/2020): – 1 click: the “Cookies — manage consents” link in the Shop footer; – 1 toggle: in the Preferences panel.

The withdrawal of consent does not affect the lawfulness of processing carried out before its withdrawal.

9.4. Inheritance of the choice across devices

The choice concerning Plausible (plausible_ignore) is stored solely in the local storage of the specific browser. The Operator does not link this preference to the Purchaser’s account — the choice must be made separately on each device / in each browser the Purchaser uses. This decision serves to minimise the linking of identifiers.


§ 10. Impact on the functioning of the Shop following refusal

10.1. Strictly necessary cookies — refusal means no Shop

Refusing strictly necessary cookies is technically impossible within the Operator’s banner — the banner does not contain an option to disable strictly necessary cookies, because the Shop cannot function without them. The Purchaser may refuse strictly necessary cookies only at browser level (the “Block all cookies” setting). The effect: – inability to log in to the account; – inability to add products to the basket; – inability to carry out the payment process; – the need to confirm the age gate on each occasion.

10.2. Analytics / marketing cookies

None — the Operator does not use such cookies. Refusal in the banner / selecting “Reject all” results solely in an opt-out from Plausible Analytics. Plausible is cookieless, so the actual effect is that measurement events are not sent from the Purchaser’s device — the remaining Shop functions operate identically.

10.3. Browser settings

Regardless of the banner, the Purchaser may manage cookies via the browser settings. Brief instructions:

Browser Path
Chrome Settings → Privacy and security → Cookies and other site data
Firefox Settings → Privacy & Security → Cookies and Site Data
Safari Preferences → Privacy → Cookies and website data
Edge Settings → Cookies and site permissions
Opera Settings → Advanced → Privacy and security → Cookies

The private / incognito mode of each of the above browsers automatically deletes session cookies once the window is closed.


§ 11. Policy amendment procedure

  1. The Operator reserves the right to introduce amendments to this Policy in the event of: a) a change in legal provisions in the area of cookies, ePrivacy, the GDPR (RODO) or the Telecommunications Law; b) the issuance of new UODO (Polish DPA) decisions, CJEU judgments or EDPB guidelines having an impact on practice; c) the introduction of new Shop functionalities requiring new cookies; d) a change of service providers (e.g. a change of analytics provider, hosting, payment gateway); e) a substantive or editorial correction or an update to the cookie table.
  2. Each material amendment to the Policy enters into force 14 days after its publication in the Shop, subject to amendments arising from mandatory provisions of law — these enter into force on the day of publication.
  3. Each amendment will be noted in the Change History (§ 13). Each amendment introducing a new cookie or changing the retention of an existing one will additionally be communicated in the re-confirm banner for returning Purchasers.
  4. The current version of the Policy is always available at https://purepoint.pl/polityka-cookies/. The Operator does not send notifications of changes individually to Purchasers.

§ 12. Bibliography and legal acts

12.1. Legal acts — Poland

  1. Act of 16 July 2004 — Telecommunications Law (consolidated text: Journal of Laws 2024 item 34, as amended) — Art. 173.
  2. Act of 23 April 1964 — Civil Code (consolidated text: Journal of Laws 2024 item 1061, as amended) — Art. 22(1), Art. 43(1).
  3. Act of 30 May 2014 on consumer rights (consolidated text: Journal of Laws 2024 item 1796, as amended).
  4. Act of 10 May 2018 on the protection of personal data (consolidated text: Journal of Laws 2019 item 1781, as amended).
  5. Act of 18 July 2002 on the provision of services by electronic means (consolidated text: Journal of Laws 2024 item 1513, as amended). [VERIFY — the publication reference for the u.ś.u.d.e. has been harmonised with the Privacy Policy; to be confirmed by legal counsel]

12.2. Legal acts — European Union

  1. Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) (OJ EU L 119, 4.05.2016, p. 1, as amended) — GDPR (RODO).
  2. Directive 2002/58/EC of the European Parliament and of the Council of 12 July 2002 concerning the processing of personal data and the protection of privacy in the electronic communications sector (OJ EC L 201, 31.07.2002, p. 37, as amended, as amended by Directive 2009/136/EC) — ePrivacy.
  3. Directive 2009/136/EC of the European Parliament and of the Council of 25 November 2009 amending Directive 2002/58/EC (OJ EU L 337, 18.12.2009, p. 11).

12.3. Case law

  1. CJEU judgment of 1 October 2019, Planet49 GmbH v. Bundesverband der Verbraucherzentralen und Verbraucherverbände, C-673/17 (ECLI:EU:C:2019:801) — requirements for active consent to cookies, the impermissibility of pre-selection.
  2. CJEU judgment of 16 July 2020, Data Protection Commissioner v. Facebook Ireland Ltd and Maximillian Schrems, C-311/18 (ECLI:EU:C:2020:559) — Schrems II — invalidation of the Privacy Shield, requirements for the transfer of data to third countries.

12.4. Guidelines and decisions of authorities

  1. EDPB Guidelines 5/2020 on consent under Regulation 2016/679, version 1.1 of 4 May 2020 (European Data Protection Board).
  2. Decision of the President of the Personal Data Protection Office no. 02/2025 (administrative fine EUR 420,000) — requirements for a symmetric cookie banner.
  3. EDPB Guidelines 02/2023 on the scope and application of Art. 5 para. 3 of Directive 2002/58/EC (e-Privacy Directive), version 2.0 of November 2023.
  4. CNIL Guidelines of 17 September 2020 (deliberation 2020-091) — requirements for analytics cookies exempt from the consent obligation.

12.5. Operator’s internal documents

  1. Privacy Policy of the purepoint.pl Shop, document no. 06, version 2.0 of 6 June 2026.
  2. Terms and Conditions of the purepoint.pl Shop, document no. 01, version 2.0 of 6 June 2026.
  3. Record of Processing Activities (RCP), internal document of FIRSTSTONE TRADING sp. z o.o.
  4. Data processing agreement with Plausible Insights OÜ of 6 June 2026 (DPA).

§ 13. Document change history

Version Date Author Scope of changes
1.0 2026-05-22 FIRSTSTONE TRADING sp. z o.o. (compliance team) First version of the Cookies Policy for the purepoint.pl Shop. Assumptions: Google Analytics 4 with IP anonymisation, a standard 2-button banner (Accept / Customise), Consent Mode v2.
1.0.1 2026-05-24 FIRSTSTONE TRADING sp. z o.o. Minor editorial corrections to the cookie table; addition of the Polylang cookie (pll_language). No changes at the legal level.
2.0 2026-06-06 FIRSTSTONE TRADING sp. z o.o. Strategic change: abandonment of Google Analytics 4 in favour of Plausible Analytics (cookieless, EEA). Implementation of a symmetric 3-button banner (Accept all / Reject all / Customise) following the UODO (Polish DPA) decision 02/2025. Addition of section § 5 (justification for the selection of Plausible). Update to the cookie table — removal of the entries _ga, _gid, _gat, _gcl_*. Addition of the compliance cookies: pp_age_gate_passed (90 days), pp_compliance_acks, pp_consent_record (12 months). Addition of a Plausible opt-out mechanism (plausible_ignore). Update to the bibliography — addition of Planet49 (C-673/17), UODO (Polish DPA) 02/2025, EDPB 5/2020, EDPB 02/2023, CNIL deliberation 2020-091. Introduction of the terminology “Purchaser / Qualified Purchaser” consistent with Terms and Conditions v2.

§ 14. Final clause

In matters not regulated by this document, the mandatory provisions of Polish and European Union law shall apply. In the event of any doubts as to interpretation, please contact compliance@purepoint.pl.


FIRSTSTONE TRADING sp. z o.o. ul. Wierzbięcice 44A/40A, 61-568 Poznań, województwo wielkopolskie KRS 0001254766 | NIP 7831958614 District Court Poznań – Nowe Miasto i Wilda in Poznań, VIII Commercial Division of the KRS Share capital: PLN 5,000.00 ADE: AE:PL-21312-60691-FGBFV-19

Cookies Policy and ePrivacy — version 2.0 Effective date: 6 June 2026 Representation: Krystian Dawidowski — Member of the Management Board

Other Legal Center documents

  • Research Disclaimer
  • Product Disclaimer
  • Acceptable Use Policy
  • Store Terms & Conditions
  • Shipping Policy
  • Returns Policy
  • Complaints Policy
  • Consumer Clauses B2C vs B2B
  • Privacy Policy
  • User Account Terms
  • Newsletter Terms
  • Compliance Notice
  • AML/KYC Policy
  • Sanctions & Export Policy
  • Impressum / Operator Details

Back to the Legal Center — full list of 15 documents

Research newsletter
New write-ups and documentation — straight to your inbox.
purepoint SUPPLY

Laboratory-grade research materials. Verified purity. Batch documentation on every SKU.

Navigation
  • Shop
  • Quality
  • FAQ
  • About
  • Contact
Legal Center

Positioning

  • Research Disclaimer
  • Product Disclaimer
  • AUP

Sales

  • Terms & Conditions
  • Shipping Policy
  • Returns Policy
  • Complaints Policy
  • B2C/B2B Clauses

Privacy

  • Privacy Policy
  • Cookies Policy
  • Account Terms
  • Newsletter Terms

Compliance

  • Compliance Notice
  • Safety Data Sheets (SDS)
  • AML/KYC Policy
  • Sanctions Policy
  • Impressum
Contact
  • contact@purepoint.pl
  • compliance@purepoint.pl
  • @PUREPOINT.pl

Legal disclaimer. All products offered by PUREPOINT Supply are intended for research and laboratory purposes only. They are not intended for human or animal consumption, are not medicinal products, dietary supplements or cosmetics, and must not be used for diagnostic or therapeutic purposes.

Operator: FIRSTSTONE TRADING sp. z o.o. · KRS 0001254766 · NIP 7831958614

© 2026 FIRSTSTONE TRADING sp. z o.o. All rights reserved.

Search products

⌘K

Enter at least 2 characters to see results.

Popular

Searching…

No results for your query.

Try entering a peptide name (e.g. „BPC-157”) or a category (e.g. „regeneration”).

    Full product catalogue → Research materials — for laboratory use only.
    ✓
    Added to cart

    Frequently studied together

    Go to cart →
    Research guide Build the peptide stack your research calls for Pick your direction — we curate the set and explain every choice. Build my stack
    Build my stack
    PurePoint is a brand of FIRSTSTONE TRADING sp. z o.o. — a registered Polish company. KRS 0001254766 · NIP PL7831958614 · Verify us in the KRS register ↗
    Shipped from Poland · VAT invoice · COA for every batch · contact: contact@purepoint.pl
    Materials for research purposes only. Not for human or animal consumption.
    DA/EN/PL
    Research access verification

    Laboratory-grade research materials

    PUREPOINT Supply provides research compounds strictly for laboratory use. Before entering the site, confirm your qualification and research intent.

    For research purposes only. All PUREPOINT products are intended exclusively for research and laboratory use in vitro. They are not intended for consumption or use by humans or animals. They are not medicines, dietary supplements, cosmetics or medical devices and may not be used for diagnostic or therapeutic purposes.

    Select all consents to continue.

    By entering the site you accept PUREPOINT Supply's Research Disclaimer, Terms and Privacy Policy (FIRSTSTONE TRADING sp. z o.o., NIP 7831958614, KRS 0001254766).